← IdenTrust Services, LLC cases
Bugzilla #1933353
Certificate Problem Report
IdenTrust: Incorrect response for OCSP validation
RESOLVED
FIXED
IdenTrust Services, LLC
AI Summary
IdenTrust experienced an issue with a limited number of TLS certificates returning unauthorized OCSP responses during a maintenance window on November 23, 2024. The problem was quickly identified and remediated, with a full incident report detailing the root cause and corrective actions taken. The root cause was linked to a new API deployment that mismanaged database time zone differences. All action items have been completed, including enhancements to logging and alert systems to prevent future occurrences.
Chronology
- Issue discovered during maintenance window
- REST API issue resolved
- Logging capabilities for OCSP responders deployed
- Bug queued for closure
Participants
IdenTrust
Ben Wilson
External References
Similar Local Cases
IdenTrust: Invalid OrganizationIdentifier in S/MIME certificates
IdenTrust: OCSP Signer Certificate Missing No-Check Extension
IdenTrust: Missing Revocation Reasons in CRL
IdenTrust: Bad OCSP Responses
IdenTrust: CA Certificate not published in DER Encoded Format
IdenTrust: Temporarily Expired CRLs
IdenTrust: Pre-certificates without a final certificate showing OCSP error
IdenTrust: Failure to provide OCSP responses for valid ICA certificates